dc 0fa5da8abf
Build / Build-and-ng-test (pull_request) Successful in 5m19s
Lighthouse Checks / lighthouse (pull_request) Successful in 20m53s
Build / Build-and-test-development (pull_request) Successful in 25m7s
fix(security): accept the format-catalog form when validating a libds
mpe_accesscheck and validatefilter validated their libds input with
mp_validatecol(LIBDS), which rejects the LIBREF.CATALOGNAME-FC form that
Data Controller uses to address a format catalog.  A format-catalog load
or filter therefore aborted with "Invalid base_table" / "Invalid
filter_table" - stagedata, getdata and postdata all reach mpe_accesscheck
through the edit/approve path.

Add mpe_validatecol, a wrapper that permits the catalog form: the -FC
suffix is matched exactly and the remainder is validated as a strict
LIBREF.DATASET, so the whole value is covered and a caller that needs the
catalog reference downstream (MPE_SECURITY stores it with the suffix)
still receives it.  getrawdata and getcolvals had grown an inline version
of this check that scanned on the dash and validated only the prefix,
leaving whatever followed it unvalidated; the wrapper replaces both.

mpe_validatecol.test.sas asserts the matrix - plain libds, catalog form,
and payloads that smuggle content past a valid libds prefix.
2026-09-22 11:23:37 +00:00
2026-08-27 17:21:01 +01:00
2026-05-01 11:46:10 +01:00
2023-07-13 13:44:05 +02:00
2026-09-17 16:34:55 +00:00
2023-07-25 09:09:57 +01:00
2026-09-17 16:34:55 +00:00
2026-06-15 14:42:18 +02:00

Data Controller for SAS

Control your manual data modifications!

Alternatives to Data Controller include:

  • 💾 Developing / testing / deploying / scheduling overnight batch jobs to load files from shared drives
  • 🔒 Opening (and locking) datasets in Enterprise Guide or SAS® Table Viewer to perform direct updates
  • Asking a #DBA to run validated code after a change management process
  • 🌐 Building & maintaining your own custom web application
  • 🏃 Running #SAS or #SQL updates in production

Problems with the above include:

  • Legacy 'black box' solutions with little to no testing, documentation or support
  • End users requiring direct write access to critical data sources in production
  • Upload routines that must be manually modified when the data model changes
  • Breaches due to unnecessary parties having access to the data
  • Inability to trace who made a change, when, and why
  • Reliance on key individuals to perform updates
  • Building bespoke ETL for every new data source
  • High risk of manual error / data corruption

Data Controller for SAS® solves all these issues in a simple-to-install, user-friendly, secure, documented, battle-tested web application. Available on Viya, SAS 9 EBI, and SASjs Server.

An individual Viya deploy can be done in just 2 lines of #SAS code!

filename dc url "https://git.datacontroller.io/dc/dc/releases/download/latest/viya.sas";
%inc dc;

For a multi-user deploy, using a shared system account, please see deploy docs.

For further information:

For support, contact support@4gl.io or reach out on Matrix!

Development

Lighthouse CI

This project includes automated Lighthouse performance and accessibility checks that run on pull requests. The checks ensure:

  • Accessibility Score: Minimum 1.0 (100%) median score across all tested pages

The Lighthouse CI workflow:

  1. Sets up the development environment with SASjs server and mocked services
  2. Builds and serves the Angular frontend
  3. Installs Chrome and runs lhci autorun (Lighthouse CI) against key pages
  4. Uploads results as artifacts for review

To run Lighthouse checks locally:

cd client
npm install
npm run lighthouse

Configuration is in client/lighthouserc.js (URL list, desktop preset, Chrome flags, assertions).

S
Description
Capture, Review, Approve. This repo contains the source code (and release assets) for the Data Controller application.
https://datacontroller.io
Readme
41 MiB
v7.14.1
Latest
2026-09-17 16:34:55 +00:00
Languages
TypeScript 47.1%
SAS 24.5%
JavaScript 13.7%
HTML 10.6%
SCSS 3.3%
Other 0.8%